Cyber Defense Incident Responder - Junior

WASHINGTON, DC, US • Posted 1 hour ago • Updated 1 hour ago
Full Time
On-site
USD $75,000.00 - 89,000.00 per year
Fitment

Dice Job Match Score™

🔗 Matching skills to job...

Job Details

Skills

  • Information Technology
  • Trend Analysis
  • Reporting
  • Security Architecture
  • Risk Management
  • Meta-data Management
  • Research
  • IDS
  • Packet Analysis
  • Access Control
  • ACL
  • System Administration
  • Operating Systems
  • Hardening
  • Information Security
  • Network Layer
  • Distribution
  • Communication
  • LAN
  • WAN
  • WLAN
  • WWAN
  • DLL
  • Information Assurance
  • Sensors
  • Data Analysis
  • Intelligence Analysis
  • Cloud Computing
  • Tablet
  • Security Clearance
  • Malware Analysis
  • Dependability
  • Incident Management
  • Network
  • Intrusion Detection
  • Snort
  • Security Controls
  • NIST SP 800 Series
  • Privacy
  • Authentication
  • SAP BASIS
  • Law
  • Artificial Intelligence
  • Cyber Security
  • Partnership
  • Innovation
  • Accountability

Summary

Job Description

Everforth ECS is seeking a Cyber Defense Incident Responder - Junior to work in our Washington, DC office.

Everforth ECS Federal is a leading information security and information technology company in Fairfax, VA. We are looking to hire a Junior Cyber Defense Incident Responder to support a full range of cyber security services on a long-term contract in Washington DC. The position is full time/permanent and will support a US Government civilian agency. The position is available immediately upon finding a qualified candidate with the appropriate background clearance.

Position Responsibilities:
  • Develop content for cyber defense tools.
  • Characterize and analyze network traffic to identify anomalous activity and potential threats to network resources.
  • Coordinate with enterprise-wide cyber defense staff to validate network alerts.
  • Ensure that cybersecurity-enabled products or other compensating security control technologies reduce identified risk to an acceptable level.
  • Document and escalate incidents (including event's history, status, and potential impact for further action) that may cause ongoing and immediate impact to the environment.
  • Perform cyber defense trend analysis and reporting.
  • Perform event correlation using information gathered from a variety of sources within the enterprise to gain situational awareness and determine the effectiveness of an observed attack.
  • Perform security reviews and identify security gaps in security architecture resulting in recommendations for inclusion in the risk mitigation strategy.
  • Identify and analyze anomalies in network traffic using metadata.
  • Conduct research, analysis, and correlation across a wide variety of all source data sets (indications and warnings).
  • Validate intrusion detection system (IDS) alerts against network traffic using packet analysis tools.
Salary Range: $75,000- $89,000
General Description of Benefits

Required Skills

  • Strong written and verbal communication skills.
  • Ability to interpret the information collected by network tools (e.g., Nslookup, Ping, and Traceroute).
  • Knowledge of host/network access control mechanisms (e.g., access control list, capabilities lists).
  • Knowledge of vulnerability information dissemination sources (e.g., alerts, advisories, errata, and bulletins).
  • Knowledge of incident response and handling methodologies.
  • Knowledge of front-end collection systems, including traffic collection, filtering, and selection.
  • Experience with system administration, network, and operating system hardening techniques.
  • Knowledge of cyber defense and information security policies, procedures, and regulations.
  • Knowledge of the common attack vectors on the network layer.
  • Knowledge of different classes of attacks (e.g., passive, active, insider, close-in, distribution attacks).
  • In-depth understanding of cyber attackers (e.g., script kiddies, insider threat, non-nation state sponsored, and nation sponsored).
  • Knowledge of various types of network communication (e.g., LAN, WAN, MAN, WLAN, WWAN).
  • Knowledge of file extensions (e.g., .dll, .bat, .zip, .pcap, .gzip).
  • Knowledge of front-end collection systems, including traffic collection, filtering, and selection.

Certifications/Licenses:
  • Bachelor's degree or higher
  • 4+ years' experience in Introductory information assurance, networks, sensor operations, network/data analysis, packet capture analysis, hunts methodologies, intelligence analysis
  • Certifications addressing new attack vectors (emphasis on cloud computing technology, mobile platforms and tablet computers), new vulnerabilities, existing threats to operating environments
  • Active Secret clearance or eligible to obtain a Secret clearance


Desired Skills

  • Experience in detecting host and network-based intrusions via intrusion detection technologies (e.g., Snort).
  • Ability to analyze malware, conduct vulnerability scans, and recognize vulnerabilities in security systems.
  • Skill in determining how a security system should work (including its resilience and dependability capabilities) and how changes in conditions, operations, or the environment will affect these outcomes.
  • Experience evaluating the adequacy of security designs.
  • Skill in using incident handling methodologies.
  • Ability to apply techniques for detecting host and network-based intrusions using intrusion detection technologies.
  • Experience with using protocol analyzers and collecting data from a variety of cyber defense resources.
  • Experience reading and interpreting signatures (e.g., snort).
  • Experience with assessing security controls based on cybersecurity principles and tenets. (e.g., CIS CSC, NIST SP 800-53, Cybersecurity Framework, etc.)
  • Ability to accurately and completely source all data used in intelligence, assessment and/or planning products.
  • Ability to apply cybersecurity and privacy principles to organizational requirements (relevant to confidentiality, integrity, availability, authentication, non-repudiation).
#EverforthECS1

ECS Federal LLC is an equal opportunity employer and does not discriminate or allow discrimination on the basis any characteristic protected by law. All qualified applicants will receive consideration for employment without regard to disability, status as a protected veteran or any other status protected by applicable federal, state, or local jurisdiction law.

Everforth ECS is the federal segment of Everforth , a $4B global organization with over 10,000 employees. Our nearly 3,500 professionals deliver advanced technology solutions in data and AI, cybersecurity, and enterprise transformation, serving defense, intelligence, and federal civilian agencies.

Our work powers mission-critical outcomes, strengthens technology partnerships, and creates meaningful opportunities for our people. We are defined by a commitment to excellence in delivery, a culture of innovation, and an environment where talent can thrive and grow.

We value:
  • Attracting and developing top talent and high-performing teams
  • Fostering a culture that is engaging, accountable, and mission-driven

Meet the challenge. Make a difference with Everforth ECS!
Employers have access to artificial intelligence language tools (“AI”) that help generate and enhance job descriptions and AI may have been used to create this description. The position description has been reviewed for accuracy and Dice believes it to correctly reflect the job opportunity.
  • Dice Id: 10112MAN
  • Position Id: 3841
  • Posted 1 hour ago
Create job alert
Set job alertNever miss an opportunity! Create an alert based on the job you applied for.

Similar Jobs

Arlington, Virginia

Today

Full-time

Arlington, Virginia

Today

Full-time

Arlington, Virginia

Today

Full-time

McLean, Virginia

Today

Full-time

Search all similar jobs